A new Android attack combines malware and ransomware in a cocktail of cybercrime
- Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware
- Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk
- Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom
When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor.
Rarely do we see all of these functionalities merged into a single entity, and even rarer – to have it target Android mobile devices – yet, security researchers Zimperium discovered just that.
Mantax Otax
The security outfit published an in-depth report on Mantax Otax, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general.
Latest Videos FromTechRadar
The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.
Mantax Otax primarily targets users sporting older Android phones. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:
“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application’s localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”
Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Another important caveat is the permissions. As is usual on Android devices, most malware won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images.
It then requests accessibility permissions, fully taking over the compromised device.
Malicious capabilities
Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs.
Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities.
Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.
The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.
There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are.
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom When threat actors target people’s devices, they usually…
Recent Posts
- A new Android attack combines malware and ransomware in a cocktail of cybercrime
- Bose QuietComfort Headphones (2nd gen) review: Upgraded in all the right places
- Arizona’s lifeline for chip manufacturing is drying up
- Amazon surprises us with its best-ever deal on the Kindle Scribe — get the 4.5-star ereader and e-ink tablet for its lowest-ever price
- Insta360 launches a single-lens Osmo Pocket rival you can actually buy in the US
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023